Epic Pauses Product Development to Fix Security Vulnerabilities
AI

Epic Pauses Product Development to Fix Security Vulnerabilities

TechNews Editorial
TechNews EditorialOct 2, 2026 · 2 min read
Share

Why it matters

The pause at Epic highlights growing concerns that artificial intelligence tools can rapidly find vulnerabilities in critical healthcare software used by millions.

The facts

  • Epic has paused most product development for six weeks to fix security bugs found by an artificial intelligence model.
  • The flaws in MyChart could allow outsiders to access patient records without leaving software logs.
  • MyChart maintains over 320 million patient records across hospitals and doctor offices in the United States.

Medical technology giant Epic has paused most of its product development. The company is working to protect its software and systems from cyberattacks. MyChart software for accessing patients medical data is created by this company.

Judy Faulkner is the founder and chief executive of Epic. She told Modern Healthcare last month that the pause would likely last six weeks. Work continues on safeguarding company products during this period.

AI cybersecurity model unearthed flaws

An artificial intelligence tool triggered the security fix. Epic deployed Anthropic frontier cybersecurity model Mythos. The deployment unearthed security flaws that could allow access to patients data.

Epic has not disclosed the nature of the bugs. Stirling Martin serves as the chief security officer for the company. He told The New York Times that some customer configurations of MyChart could allow outsiders to access patient records without recording any intrusion in the software logs.

Martin did not return requests for comment from TechCrunch. He told the Times that the artificial intelligence model did not say if the bug could be exploited to alter patient records without detection. He argued it was enough of a risk to remediate the issues.

A healthcare portal displays private patient records while its adjacent access history shows no corresponding new entry.
Illustration: AI & Tech News

MyChart maintains millions of records

MyChart is widely used across the United States. The software maintains over 320 million patient records across hospitals and doctor offices. Epic states it does not have access to customers medical data. Responsibility falls on healthcare providers like hospitals and doctor offices.

A bug unknown to Epic could allow hackers to compromise multiple MyChart affected systems located across the United States. Attackers could raid the data stored within. Healthcare breaches are increasingly common as hackers seek access to sensitive health data.

Read nextCalifornia Attorney General Subpoenas OpenAI Over AI Agent Escapes

Hackers assume providers will pay to prevent the publication of information online. A 2024 ransomware attack on Change Healthcare allowed hackers to steal health data on more than 192 million people. Change Healthcare is owned by insurance giant UnitedHealth and handles payments for most Americans. That company paid hackers twice not to publish the stolen data.

Back-to-back data breaches have affected tens of millions of Americans this year. Medical records were stolen during a breach at CareCloud. Millions of rows of patient data were taken from McKesson. An unspecified amount of data was stolen from Craneware.

The pause will last six weeks

The Department of Health and Human Services lists a breach at DentaQuest as the largest healthcare related data breach of 2026 so far. That incident affected 15 million people. Epic continues its six week pause on product development to address the identified security vulnerabilities.

Newsletter

Get the best AI & tech news daily

A concise daily digest. Unsubscribe anytime.

We use your email only to send this newsletter.

Keep reading